4.3
CVSSv2

CVE-2013-5996

Published: 21/11/2013 Updated: 21/11/2013
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in shopping/payment.tpl components in LOCKON EC-CUBE 2.11.0 up to and including 2.13.0 allow remote malicious users to inject arbitrary web script or HTML via crafted values.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

lockon ec-cube 2.12.3

lockon ec-cube 2.12.2

lockon ec-cube 2.12.1

lockon ec-cube 2.12.0

lockon ec-cube 2.11.5

lockon ec-cube 2.12.6

lockon ec-cube 2.12.4en

lockon ec-cube 2.12.3enp1

lockon ec-cube 2.11.4

lockon ec-cube 2.11.2

lockon ec-cube 2.12.3enp2

lockon ec-cube 2.12.3en

lockon ec-cube 2.11.3

lockon ec-cube 2.11.1

lockon ec-cube 2.12.6en

lockon ec-cube 2.13.0

lockon ec-cube 2.12.5en

lockon ec-cube 2.12.5

lockon ec-cube 2.11.0